Your client data, properly protected
Security and UK regulatory compliance are built into the foundation. Not bolted on afterwards.
Secure authentication
Email verification, strong password policies and mandatory TOTP two-factor authentication for every user.
Data isolation
Row-level security enforces strict per-firm isolation. Staff only see their own letters; compliance and admin have scoped access.
UK GDPR aligned
Built with UK GDPR principles: data minimisation, lawful processing, robust access controls and automated PII masking. FCA conduct rules and Consumer Duty principles applied throughout.
Immutable audit trail
Every action is permanently logged. Creation, edits, reviews and downloads. And cannot be modified or deleted.
UK GDPR PII masking before AI
Before any meeting note text reaches the AI model, our masking gateway replaces personal details. Client names, addresses, postcodes, NI numbers, dates of birth, account references, email addresses and phone numbers. With neutral placeholders.
The AI works on the masked text only. Original values are re-injected into the structured output on your side. The AI provider never sees real client identity data.
Original meeting note
"Met with John Smith (DOB 04/12/1965) at 12 Acacia Avenue, Crewe CW1 3AB to discuss his SIPP…"
Sent to AI
"Met with [CLIENT_NAME_1] (DOB [DOB_1]) at [ADDRESS_1] to discuss his SIPP…"
Role-based access control
Granular permissions ensure team members only access what they need. Staff manage their own letters, compliance reviews all submissions, and admins oversee the entire system.
Security features
- Encrypted data at rest (AES-256) and in transit (TLS 1.2+)
- AI provider does not train on your data
- Two-factor authentication (TOTP) for enhanced account security
- 30+ Row-Level Security policies enforced at database level
- Immutable audit logging for regulatory compliance
- UK/EU data residency (London region)
- Meeting notes processed transiently. Never persisted after extraction
- Private storage buckets with time-limited signed URLs
FCA Conduct Rules & Consumer Duty
Models and prompts are tuned for regulated financial advice. FCA conduct rules, FCA Consumer Duty principles and ICO data principles are applied throughout the workflow. AI outputs remain decision-support tools and do not constitute financial advice.
Need our security pack?
We share a detailed security & compliance summary on request.